signals-scout-general
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted event data from the PostHog project, creating a surface for indirect prompt injection.
- Ingestion points: Data is ingested via tools such as
read-data-schema,execute-sql,query-logs, andinbox-reports-retrieveinSKILL.md. - Boundary markers: The instructions do not specify explicit delimiters or boundary markers when interpolating retrieved data into prompts for analysis.
- Capability inventory: The skill can perform write actions via
emit_report,edit_report, andscout-scratchpad-remember. - Sanitization: There are no documented sanitization or filtering steps for the ingested data before it is processed by the agent.
Audit Metadata